HIPAA
The regulatory floor for anyone handling protected health information, and the entry point to healthcare deals.
What it is
HIPAA is regulation, not certification. The Security Rule requires administrative, physical, and technical safeguards; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets disclosure obligations. Compliance is demonstrated through a documented risk analysis, implemented safeguards, workforce training, and executed business associate agreements — there is no certificate, so buyers assess your program directly or ask for HITRUST instead.
Who typically needs it
- Digital health and healthcare AI vendors signing business associate agreements
- Companies whose customers are covered entities and who are therefore business associates
- Sub-processors handling PHI on behalf of another business associate
- Organizations that signed BAAs before building the underlying program
- Vendors being asked for HITRUST who need the HIPAA foundation first
What the engagement looks like
Common failure modes
- A security questionnaire answered as though it were the risk analysis
- Addressable specifications treated as optional, with no record of the alternative applied
- BAAs signed with terms the program cannot meet, particularly on breach notification timelines
- Training completed but not evidenced, which fails almost every payer diligence review
Price range
Programs typically run between $20,000 and $50,000 for the Build phase, depending on PHI footprint and BAA population.
Talk to us about your HIPAA.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.